Catalog WADComs

WAD · Tool

SweetPotato

1 technique Windows · ActiveDirectoryWADComs GPL-3.0

SweetPotato-SeImpersonate

NEW
Privilege EscalationExecution WindowsActiveDirectory

SweetPotato bundles several SYSTEM-coercion primitives (EfsRpc, DCOM/RoguePotato-style OXID, PrintSpoofer, PetitPotam, WinRM) behind one binary, selected with -e, so you can fall back to whichever named-pipe or DCOM coercion the host permits. It captures the coerced SYSTEM token and launches the program in -p with the arguments in -a. Handy on IIS/MSSQL service accounts when you want to try multiple potato techniques without swapping tools. Requires SeImpersonatePrivilege. Command Reference: Privilege required: SeImpersonatePrivilege Exploit mode: EfsRpc

# -e selects the coercion primitive (EfsRpc | DCOM | WinRM | PrintSpoofer | PetitPotam)
SweetPotato.exe -p C:\Windows\System32\cmd.exe -a "/c whoami" -e EfsRpc
Native
PrivEsc, Exploitation
Requires
Shell
Services
DCOM, RPC